NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48724 | CVE-2009-1448 | Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-29 | View | |
| 6485 | CVE-2008-6754 | The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky. | 2 | 4 | Medium | 2017-01-03 | 2009-04-29 | View | |
| 6500 | CVE-2008-6769 | Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | 2 | 6 | Medium | 2017-01-03 | 2009-04-29 | View | |
| 6501 | CVE-2008-6770 | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt. | 2 | 5 | Medium | 2017-01-03 | 2009-04-29 | View | |
| 6502 | CVE-2008-6771 | YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function. | 2 | 5 | Medium | 2017-01-03 | 2009-04-29 | View |
Page 3027 of 17672, showing 5 records out of 88360 total, starting on record 15131, ending on 15135